Any "HTML emails" get filtered straight into the spam folder here. I think I'm not part of the target audience here.

How do you deal with things like "we sent you a one-time code to confirm your login"? Most of those are HTML-formatted today

I still can check the SPAM folder, if needed.

But most SPAMs are HTML, so you'll have a good default last-stage in-client filtering in place in case some SPAM actually makes it through the other setup on the server (greylisting, DNS based filtering lists, policy-based filtering, etc.) :)

Is that a thing? Is it safer to use plain text emails?

> Is that a thing?

There must be literally dozens of people who do this.

Very much so. While a lot of mail clients block images, they can be used to track you. Hell a lot of HTML can be used to track you if you're smart about it